๐ช๐ธ
10dencehispahard SL
2024-04-14 18:01:17
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-04-13 07:21:46
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 13 03:21:38.357951 2024] [security2:error] [pid 9405] [client 199.249.230.70:58832] [client 199.249.230.70] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||suefellows.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "suefellows.com"] [uri "/uefellows.sql"] [unique_id "ZhoygtBqzYJiwijgXGZpsQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2024-02-14 17:18:37
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-14 15:06:16
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 14 10:06:09.636854 2024] [security2:error] [pid 22066] [client 199.249.230.70:46142] [client 199.249.230.70] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||antiterrorismbooks.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "antiterrorismbooks.com"] [uri "/orismbooks.sql"] [unique_id "ZczW4fewnNRdLl8zUn8GTAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
sms.ru
2024-02-14 00:45:07
(2 years ago)
SMS pumping attack (request flood from TOR)
DDoS Attack
Anonymous
2024-02-13 14:08:25
(2 years ago)
apache-wordpress-login
Brute-Force
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-12 23:54:22
(2 years ago)
Web Attack ([13/Feb/2024:00:54:16 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-12 23:54:22
(2 years ago)
Web Attack multi (Feb 24 00:54:21 Matching rules: Detect possible SQL injection - Too many SQL keyw ...
show more
Web Attack multi (Feb 24 00:54:21 Matching rules: Detect possible SQL injection - Too many SQL keywords (more than 3 times),Detect possible SQL injection - E.g. CHR(72),Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-12 20:50:52
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 12 15:50:47.245236 2024] [security2:error] [pid 20160] [client 199.249.230.70:56672] [client 199.249.230.70] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||communiongatherings.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "communiongatherings.com"] [uri "/mmuniongatherings.sql"] [unique_id "ZcqEp_yyix9aXmI_y7OOtQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-02-12 10:58:50
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-12 07:26:54
(2 years ago)
Web Attack multi (Feb 24 08:26:53 Matching rules: Detect possible SQL injection - Too many SQL keyw ...
show more
Web Attack multi (Feb 24 08:26:53 Matching rules: Detect possible SQL injection - Too many SQL keywords (more than 3 times),Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-11 13:52:02
(2 years ago)
Web Attack ([11/Feb/2024:14:51:51 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-11 05:08:58
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 11 00:08:53.071138 2024] [security2:error] [pid 12744] [client 199.249.230.70:53148] [client 199.249.230.70] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eileensharaga.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eileensharaga.com"] [uri "/daily.sql"] [unique_id "ZchWZUit9qffMQTHNNqUcgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-11 02:13:53
(2 years ago)
Web Attack multi (Feb 24 03:13:53 Matching rules: Detect possible SQL injection - E.g. Sleep(5) )
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-11 02:12:02
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 199.249.230.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 10 21:11:56.372268 2024] [security2:error] [pid 22793] [client 199.249.230.70:33798] [client 199.249.230.70] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.globaltechnologybuildingsystems.com"] [uri "/.git/config"] [unique_id "Zcgs7BsQqBf0dEZcGyruOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack